12 KiB
2026-07-09 — Sif-oidak: dortega AD account, printer error 740, UPN decision
User
- User: Howard Enos (howard)
- Machine: Howard-Home
- Role: tech
Session Summary
Howard reported that Dwayne Ortega could not log in to his machine at Sif-oidak District. Investigation via GuruRMM against the domain controller found no on-prem AD account matching ortega or dwayne among the 71 domain users. Ortega existed only as an M365 cloud user, created 2026-06-03. dsregcmd on Sif-Laptop554 showed the workstations are DomainJoined: YES / AzureAdJoined: NO, so an M365 credential can never authenticate a Windows sign-in at this client. His cloud password had already been reset earlier the same day (lastPasswordChangeDateTime: 2026-07-09T20:33:05Z), which could not have fixed a machine login.
The wiki described Sif-oidak as a hybrid AD/M365 environment. That was verified false: neither SIF-SERVER nor SIF-SERVER2 has an ADSync service or an Azure AD Connect uninstall entry, no AD object carries an msDS-ConsistencyGuid, and every M365 user has onPremisesSyncEnabled: null. The two directories are fully disjoint. jalbert's AD UPN is jalbert@SifOidak.local while his M365 UPN is jalbert.sod@sifoidak.onmicrosoft.com — unrelated accounts belonging to the same person.
On Howard's instruction, AD user dortega was created on SIF-SERVER via GuruRMM -EncodedCommand dispatch, matching the client's existing conventions. The account was verified enabled with pwdLastSet=0 (must change password at next logon) and confirmed replicated to both DCs. In the course of that verification SIF-SERVER2 was confirmed as a backup domain controller (DomainRole: 4), closing an open question outstanding since May. The temp credential was vaulted and pushed.
A second issue was then raised: jalbert getting an error adding the "#740 sharp ud3" printer. The #740 turned out to be the error code, not part of the printer name. Error 740 is ERROR_ELEVATION_REQUIRED, matching Error code= 800702e4 (0x2E4 = 740) in three PrintService/Admin event-600 entries. Root cause is the post-KB5005652 default RestrictDriverInstallationToAdministrators=1, which blocks non-admin print-driver installs via Point and Print; jalbert is not a local admin. Howard confirmed the UAC prompt for the driver install never surfaced, so it presented as a bare error. Howard installed the printer himself; no remote change was dispatched.
Finally, Mike's standing instruction was captured: new Sif-oidak users must get both an AD account and an M365 account. The related request to drop onmicrosoft.com from usernames was investigated and closed as not actionable — the tenant's only verified domain is sifoidak.onmicrosoft.com, and using @sifoidak.com would require a DNS TXT verification record at GoDaddy, where ACG has no registrar access (Mike confirmed).
Key Decisions
- Created the AD account rather than resetting the cloud password again. The cloud password had already been reset that day to no effect. Machine sign-in at this client is AD-only; no M365 change could ever fix it.
- Placed dortega in
Domain Usersonly. jalbert is also inAssistancePrograms Group, but that is a departmental group and membership was not assumed. Flagged for confirmation. - Declined to set
RestrictDriverInstallationToAdministrators=0as a printer fix. That re-opens the PrintNightmare (CVE-2021-34527) RCE class for every user on the machine. The safe non-interactive alternative (per-machine connection added as SYSTEM viaprintui /ga) was prepared but not dispatched — Howard fixed it manually first. - Recorded the UPN rename as DECIDED, not BLOCKED. Framing it as blocked would invite a future session to re-propose it. It is closed pending registrar access that we are not pursuing.
- Corrected the wiki's "hybrid" description. That single wrong word is what makes the two-account trap easy to fall into, and it directly caused this ticket.
Problems Encountered
get-token.shresolvedidentity.jsonfrom$HOMEinstead of the repo, dying withvault_path not set. Worked around withexport VAULT_ROOT_ENV=D:/vault. Logged to errorlog as friction.- UNC path
\\SIF-SERVER\print$collapsed to a single backslash inside ajq --argPowerShell payload, producing a bogus "path not found" that nearly read as a real diagnostic finding. Re-dispatched byte-exact viaps-encoded.sh. Logged to errorlog as friction (reffeedback_windows_quote_stripping). - A rejected
git pushreported[OK]. The chaingit push -q 2>&1 | tail -5 && echo "[OK]"testedtail's exit status, not git's. The vault push had actually been rejected (remote ahead). Fixed withgit pull --rebasethen a baregit push. Logged to errorlog as friction. signInActivityquery returned 403 —AuditLog.Read.Allis still missing on the Security Investigator SP for this tenant, so sign-in history could not be read. This is the known open item from 2026-06-03, re-confirmed still outstanding.- Laptop agent UUIDs in the wiki were stale — both laptops had re-enrolled since May. Corrected, with a warning to always resolve hostname → UUID live.
Configuration Changes
| File | Change |
|---|---|
wiki/clients/sif-oidak.md |
Rewrote identity model (not hybrid); added Identity model, Printing, and User Onboarding Runbook sections; corrected agent UUIDs; confirmed SIF-SERVER2 as backup DC; closed UPN item; two history entries |
D:/vault/clients/sif-oidak/ad-users.sops.yaml |
Created — dortega AD credential (SOPS-encrypted, pushed) |
errorlog.md |
3 --friction entries (get-token identity resolution, UNC backslash mangling, piped-exit-code false OK) |
AD change (SIF-SERVER): created user dortega.
Credentials & Secrets
dortegaon-prem AD account — vaulted atclients/sif-oidak/ad-users.sops.yaml. Temp password is single-use:pwdLastSet=0forces a change at first logon, invalidating it. Read with:bash .claude/scripts/vault.sh get-field clients/sif-oidak/ad-users.sops.yaml credentials.dortega_temp_password- Password was never pasted into chat, a ticket, or a commit message.
- ACG has no GoDaddy/registrar credentials for
sifoidak.com. Confirmed absent from vault; Mike confirmed we cannot obtain them. - Existing:
clients/sif-oidak/laptops.sops.yamlholdsLocaladmin/Siflocal creds for the laptops.
Infrastructure & Servers
| Host | Role | GuruRMM agent ID | Notes |
|---|---|---|---|
| SIF-SERVER | PDC (DomainRole: 5) |
def9fdbb-020b-498d-9d3b-edf5912ba298 |
Shares SHARP UD3 PCL6 + MX-6070V PCL6 |
| SIF-SERVER2 | Backup DC (DomainRole: 4, confirmed this session) |
944b0c4b-048d-44b8-85e5-40da135f58d6 |
Shares SHARP MX-6240N PCL6 |
| Sif-Laptop554 | jalbert's laptop | 9e5016f0-e330-4d24-ab01-67cf4e55d46b |
Online; UUID changed since May |
| Sif-Laptop555 | likely Ortega's (unconfirmed) | 1be314d5-0395-4b1c-aa26-3b4a96bd2e22 |
Offline; UUID changed since May |
- AD domain:
SifOidak.local— 71 users. Only UPN suffix in the forest. - AD password policy:
MinPasswordLength: 6,ComplexityEnabled: False,MaxPasswordAge: ~42d. - M365 tenant:
sifoidak.onmicrosoft.com, tenant ID568eb763-3b95-4271-8443-530c74b1c6bb.- Only verified domain:
sifoidak.onmicrosoft.com(isInitial,isDefault). - SKU
O365_BUSINESS, 11/11 consumed. Service plans includeEXCHANGE_S_FOUNDATION(no-mailbox stub),OFFICE_BUSINESS,ONEDRIVESTANDARD. - No Exchange mailboxes exist. All 12 users:
mail: null, zeroproxyAddresses.
- Only verified domain:
- Email:
sifoidak.comat GoDaddy —NS ns19/ns20.domaincontrol.com,MX 0 smtp.secureserver.net,MX 10 mailstore1.secureserver.net. Outside M365 entirely. - Printers: all three queues use
PortName 192.168.0.99. - Parent org
tonation-nsn.govhasMX -> tonationnsn-gov02b.mail.protection.outlook.com(separate tenant, not ours).
Commands & Outputs
Find the client's agents:
bash .claude/scripts/rmm-search.sh -c "sif-oidak"
Confirm no AD account existed (returned zero matches across 71 users):
Get-ADUser -Filter { Name -like "*ortega*" -or SamAccountName -like "*ortega*" } -Properties Enabled,LockedOut
Confirm no directory sync (all three checks negative on both DCs):
Get-Service -Name "ADSync","AzureADConnectHealthSync*" # none
Get-ItemProperty HKLM:\...\Uninstall\* | ? DisplayName -match "Azure AD Connect" # none
(Get-ADUser -Filter * -Properties "msDS-ConsistencyGuid" | ? {$_."msDS-ConsistencyGuid"}).Count # 0
Workstation join state (Sif-Laptop554):
AzureAdJoined : NO
DomainJoined : YES
Create the account (dispatched byte-exact via ps-encoded.sh because of the ! and quotes):
bash .claude/scripts/ps-encoded.sh rmm def9fdbb-020b-498d-9d3b-edf5912ba298 create-dortega.ps1 --timeout 120
Result — cmd:cb79dca7, exit 0:
SamAccountName : dortega
UserPrincipalName : dortega@SifOidak.local
DistinguishedName : CN=Dwayne Ortega,OU=Domain Users,DC=SifOidak,DC=local
Enabled : True
pwdLastSet : 0 <- must change at next logon
MUSTCHANGE=True
Replication verified on both DCs (Get-ADUser dortega -Server localhost → visible, pwdLastSet=0).
Printer failure — Microsoft-Windows-PrintService/Admin, event 600, ×3 on 2026-07-09:
The print spooler failed to import the printer driver that was downloaded from
\\sif-server\print$\x64\PCC\sv0emenu.inf_amd64_d930f97fabc69575.cab into the driver
store for driver SHARP UD3 PCL6. Error code= 800702e4.
0x800702e4 → Win32 error 0x2E4 = 740 = ERROR_ELEVATION_REQUIRED. The event text blames the digital signature — red herring, it is purely elevation.
# absent -> Windows default = 1 = only admins may install printer drivers
(Get-ItemProperty "HKLM:\Software\Policies\Microsoft\Windows NT\Printers" -Name RestrictDriverInstallationToAdministrators).RestrictDriverInstallationToAdministrators
# ABSENT
Get-LocalGroupMember Administrators
# SIF-LAPTOP554\Administrator, SIF-LAPTOP554\Localadmin, SIFOIDAK\Domain Admins (no jalbert)
Separate GPO defect — event 513 on Sif-Laptop554:
Group Policy was unable to add per computer connection \\SIF-SERVER\SHARP MX-6240N PCL6.
Error code 0x709.
The MX-6240N is shared on SIF-SERVER2, not SIF-SERVER. GPO path is wrong.
Graph reads (note the VAULT_ROOT_ENV workaround):
export VAULT_ROOT_ENV="D:/vault"
TOK=$(bash ~/.claude/skills/remediation-tool/scripts/get-token.sh sifoidak.onmicrosoft.com investigator | tail -1)
curl -s "https://graph.microsoft.com/v1.0/domains" -H "Authorization: Bearer $TOK"
curl -s "https://graph.microsoft.com/v1.0/subscribedSkus" -H "Authorization: Bearer $TOK"
Pending / Incomplete Tasks
- Confirm which laptop is Ortega's (Sif-Laptop555 assumed; offline this session) and verify he can sign in and complete the forced password change. He must be on the domain network for the first logon.
- Fix the GPO printer path —
\\SIF-SERVER\SHARP MX-6240N PCL6→\\SIF-SERVER2\SHARP MX-6240N PCL6. Failing on every boot today. - Backfill
AuditLog.Read.All+User.Read.Allon the Security Investigator SP:onboard-tenant.sh sifoidak.onmicrosoft.com. Sign-in history unreadable until then. Open since 2026-06-03. - Decide whether dortega needs
AssistancePrograms Groupmembership. - Consider hardening the AD password policy (min 6, complexity off).
- Determine if jalbert's
PasswordNeverExpiresshould be restored (cleared 2026-05-28). - Consider GDAP / Partner Center relationship to get the tenant into CIPP.
- No Syncro ticket or time was logged for this session. Billing rate is $150/hr remote.
Remove— CLOSED. No registrar access toonmicrosoft.comfrom M365 usernamessifoidak.com; Mike confirmed unobtainable. Do not re-open.
Reference Information
- Wiki article:
wiki/clients/sif-oidak.md - Commits:
2b6e368(identity model + printer + onboarding runbook),e570629(close UPN rename) - Vault:
clients/sif-oidak/ad-users.sops.yaml,clients/sif-oidak/laptops.sops.yaml - GuruRMM command IDs:
cb79dca7(create dortega),d72cee82(AD user search) - Syncro customer ID
7694718; prior tickets #32341, #32380 - Tenant admin consent URL:
https://login.microsoftonline.com/sifoidak.onmicrosoft.com/adminconsent?client_id=709e6eed-0711-4875-9c44-2d3518c47063&redirect_uri=https://azcomputerguru.com&prompt=consent - Error 740 background: KB5005652 / CVE-2021-34527 (PrintNightmare) Point-and-Print hardening